PT-2017-1605 · Microsoft · Iis 6.0+1

Chen Wu

+1

·

Published

2017-03-27

·

Updated

2026-01-06

·

CVE-2017-7269

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2003 R2
Description The issue is caused by a buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0. This allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request. The vulnerability has been exploited in the wild.
Recommendations For Microsoft Windows Server 2003 R2, apply the necessary patch to fix the buffer overflow vulnerability in the ScStoragePathFromUrl function. As a temporary workaround, consider restricting access to the WebDAV service in IIS 6.0 to minimize the risk of exploitation. Avoid using the If header with long URLs in PROPFIND requests until the issue is resolved.

Exploit

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2017-00750
CVE-2017-7269

Affected Products

Iis 6.0
Windows Server 2003 Sp2